US12609960B2UtilityA1

Entity maliciousness analysis using autonomous artificial intelligence agents

Priority: Filed: Jun 28, 2024Granted: Apr 21, 2026
H04L 63/1416G06N 20/20H04L 63/1441
31
PatentIndex Score
0
Cited by
27
References
21
Claims

Abstract

Techniques are described herein that are capable of performing entity maliciousness analysis using autonomous AI agents. A first autonomous AI agent selects relevant data from a corpus of data using a first selected AI tool in an AI model as a result of the relevant data being associated with an entity. A second autonomous AI agent generates a maliciousness determination, which indicates whether the entity exhibits malicious behavior, by analyzing the relevant data using a second selected AI tool in the AI model. A third autonomous AI agent generates a validity determination, which indicates whether the maliciousness determination is valid, by analyzing the maliciousness determination using a third selected AI tool in the AI model. As a result of an analysis that takes into consideration the validity determination, execution of an instruction that causes a security action to be performed with regard to the entity is triggered.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system comprising:
 a processor system; and   a memory that stores computer-executable instructions that are executable by the processor system to at least:
 execute a first autonomous artificial intelligence (AI) agent that, in response to receiving an inquiry that asks whether an entity exhibits malicious behavior, selects relevant data from a corpus of data using a first selected AI tool as a result of the relevant data being associated with the entity, wherein the first selected AI tool is selected by the first autonomous AI agent from a plurality of first AI tools in an AI model that are available to the first autonomous AI agent; 
 execute a second autonomous AI agent that, in response to receiving the relevant data from the first autonomous AI agent, generates a maliciousness determination by analyzing the relevant data using a second selected AI tool, wherein the maliciousness determination indicates whether the entity exhibits the malicious behavior, and wherein the second selected AI tool is selected by the second autonomous AI agent from a plurality of second AI tools in the AI model that are available to the second autonomous AI agent; 
 execute a third autonomous AI agent that generates a validity determination by analyzing the maliciousness determination using a third selected AI tool, wherein the validity determination indicates whether the maliciousness determination is valid, and wherein the third selected AI tool is selected by the third autonomous AI agent from a plurality of third AI tools in the AI model that are available to the third autonomous AI agent; and 
 as a result of an analysis that takes into consideration the validity determination, trigger execution of an instruction that causes a security action to be performed with regard to the entity. 
   
     
     
         2 . The system of  claim 1 , wherein the computer-executable instructions are executable by the processor system to at least:
 trigger the execution of the instruction that causes at least one of the following:
 access of a user to the entity to be blocked, or 
 a statement to be provided via a user interface, the statement indicating whether the entity exhibits malicious behavior. 
   
     
     
         3 . The system of  claim 1 , wherein the first autonomous AI agent triggers the first selected AI tool to select the relevant data from the corpus of data by providing a first AI prompt, which identifies the corpus of data, as an input to the first selected AI tool, the first AI prompt requesting selection of data that is associated with the entity from the corpus of data;
 wherein the second autonomous AI agent triggers the second selected AI tool to determine whether the entity exhibits the malicious behavior by providing a second AI prompt together with designated contextual information as inputs to the second selected AI tool, the second AI prompt requesting a determination whether the entity exhibits the malicious behavior, wherein the designated contextual information comprises the relevant data, and wherein the designated contextual information comprises context regarding the second AI prompt; and   wherein the third autonomous AI agent triggers the third selected AI tool to determine whether the maliciousness determination is valid by providing a third AI prompt together with specified contextual information as inputs to the third selected AI tool, the third AI prompt requesting a determination whether the maliciousness determination is valid, wherein the specified contextual information comprises the relevant data and the maliciousness determination, and wherein the specified contextual information comprises context regarding the third AI prompt.   
     
     
         4 . The system of  claim 1 , wherein, in response to receiving the inquiry that asks whether the entity exhibits the malicious behavior, the first autonomous AI agent identifies potentially anomalous data in at least a portion of the corpus of data using an anomaly detection tool as a result of differences between embeddings of the potentially anomalous data and a reference embedding that corresponds to at least the portion of the corpus of data being greater than differences between embeddings of other data in at least the portion of the corpus of data and the reference embedding, wherein the anomaly detection tool is selected by the first autonomous AI agent from the plurality of first AI tools in the AI model that are available to the first autonomous AI agent; and
 wherein the third autonomous AI agent generates the validity determination by analyzing the maliciousness determination and a description of the potentially anomalous data using the third selected AI tool.   
     
     
         5 . The system of  claim 4 , wherein, in response to receiving the inquiry that asks whether the entity exhibits the malicious behavior, the first autonomous AI agent identifies the potentially anomalous data in at least the portion of the corpus of data using an isolation forest tool that performs an isolation forest anomaly detection technique on at least the portion of the corpus of data, wherein the isolation forest tool is selected by the first autonomous AI agent from the plurality of first AI tools in the AI model that are available to the first autonomous AI agent. 
     
     
         6 . The system of  claim 1 , wherein, in response to receiving the inquiry that asks whether the entity exhibits the malicious behavior, the first autonomous AI agent identifies statistically anomalous data in the relevant data using an anomaly detection tool as a result of events indicated by embeddings of the statistically anomalous data occurring more than an expected number of times during a period of time, wherein the anomaly detection tool is selected by the first autonomous AI agent from the plurality of first AI tools in the AI model that are available to the first autonomous AI agent; and
 wherein the third autonomous AI agent generates the validity determination by analyzing the maliciousness determination and a description of the statistically anomalous data using the third selected AI tool.   
     
     
         7 . The system of  claim 6 , wherein, in response to receiving the inquiry that asks whether the entity exhibits the malicious behavior, the first autonomous AI agent identifies the statistically anomalous data in the relevant data using at least one of the following:
 a frequency analysis tool that performs a frequency analysis technique on the relevant data, wherein the frequency analysis tool is selected by the first autonomous AI agent from the plurality of first AI tools in the AI model that are available to the first autonomous AI agent; or   a p-value analysis tool that performs a p-value analysis technique on the relevant data, wherein the p-value analysis tool is selected by the first autonomous AI agent from the plurality of first AI tools in the AI model that are available to the first autonomous AI agent.   
     
     
         8 . The system of  claim 1 , wherein the validity determination indicates that the maliciousness determination is invalid;
 wherein the computer-executable instructions are executable by the processor system to at least:
 execute a fourth autonomous AI agent that generates an overriding validity determination by performing the analysis of the maliciousness determination and the validity determination using a fourth selected AI tool, wherein the overriding validity determination indicates whether the validity determination that is generated by the third autonomous AI agent is to be overturned, and wherein the fourth selected AI tool is selected by the fourth autonomous AI agent from a plurality of fourth AI tools in the AI model that are available to the fourth autonomous AI agent; and 
 perform the security action using the overriding validity determination. 
   
     
     
         9 . The system of  claim 8 , wherein the fourth autonomous AI agent triggers the fourth selected AI tool to determine whether the validity determination that is generated by the third autonomous AI agent is to be overturned by providing an AI prompt together with contextual information as inputs to the fourth selected AI tool,
 wherein the AI prompt requests a determination whether the validity determination that is generated by the third autonomous AI agent is to be overturned,   wherein the contextual information comprises the relevant data, the maliciousness determination, and the validity determination, and   wherein the contextual information comprises context regarding the AI prompt.   
     
     
         10 . The system of  claim 8 , wherein the computer-executable instructions are executable by the processor system further to at least:
 trigger the fourth autonomous AI agent to generate the overriding validity determination by providing an AI prompt and contextual information as inputs to the fourth autonomous AI agent,
 wherein the AI prompt specifies that a purpose of the fourth autonomous AI agent is to determine whether the validity determination is to be overturned, 
 wherein the contextual information comprises the relevant data, the maliciousness determination, and the validity determination, and 
 wherein the contextual information comprises context regarding the AI prompt. 
   
     
     
         11 . The system of  claim 8 , wherein the fourth autonomous AI agent generates a mediation report that indicates the overriding maliciousness determination; and
 wherein the computer-executable instructions are executable by the processor system further to at least:
 as a result of the fourth autonomous AI agent generating the mediation report, receive an assessment of the mediation report from a user, the assessment indicating a recommended change to be incorporated into the analysis performed by the fourth autonomous AI agent using the fourth selected AI tool; and 
 train the fourth autonomous AI agent using the assessment. 
   
     
     
         12 . A method implemented by a computing system, the method comprising:
 in response to receiving an inquiry that asks whether an entity exhibits malicious behavior, selecting, by a first autonomous artificial intelligence (AI) agent, relevant data from a corpus of data using a first selected AI tool, which is selected by the first autonomous AI agent from a plurality of first AI tools in an AI model that are available to the first autonomous AI agent, as a result of the relevant data being associated with the entity;   in response to receiving the relevant data from the first autonomous AI agent, generating, by a second autonomous AI agent, a maliciousness determination, which indicates whether the entity exhibits the malicious behavior, by analyzing the relevant data using a second selected AI tool, which is selected by the second autonomous AI agent from a plurality of second AI tools in the AI model that are available to the second autonomous AI agent;   generating, by a third autonomous AI agent, a validity determination, which indicates whether the maliciousness determination is valid, by analyzing the maliciousness determination using a third selected AI tool, which is selected by the third autonomous AI agent from a plurality of third AI tools in the AI model that are available to the third autonomous AI agent; and   as a result of an analysis that takes into consideration the validity determination, triggering execution of an instruction that causes a security action to be performed with regard to the entity.   
     
     
         13 . The method of  claim 12 , wherein selecting the relevant data from the corpus of data comprises:
 selecting, by the first autonomous AI agent, first relevant data from the corpus of data using a sampling tool, which is selected by the first autonomous AI agent from the plurality of first AI tools in the AI model that are available to the first autonomous AI agent, as a result of a first embedding that represents the first relevant data corresponding to a center of a plurality of embeddings that represent the corpus of data;   selecting, by the first autonomous AI agent, second relevant data from the corpus of data using the sampling tool as a result of a distance between a second embedding that represents the second relevant data and the first embedding being greater than distances between others of the plurality of embeddings and the first embedding;   selecting, by the first autonomous AI agent, third relevant data from the corpus of data using the sampling tool as a result of a first distance or a second distance, whichever is less, being greater than third distances or fourth distances, whichever are less;
 wherein the first distance is between a third embedding that represents the third relevant data and the first embedding; 
 wherein the second distance is between the third embedding and the second embedding; 
 wherein the third distances are between others of the plurality of embeddings and the first embedding; and 
 wherein the fourth distances are between the others of the plurality of embeddings and the second embedding. 
   
     
     
         14 . The method of  claim 13 , wherein selecting the first relevant data comprises:
 selecting, by the first autonomous AI agent, the first relevant data from the corpus of data using the sampling tool as a result of the embedding that represents the first relevant data corresponding to an average of the plurality of embeddings or a median of the plurality of embeddings.   
     
     
         15 . The method of  claim 12 , wherein selecting the relevant data from the corpus of data comprises:
 clustering, by the first autonomous AI agent, subsets of the corpus of data into respective clusters using a clustering tool, which is selected by the first autonomous AI agent from the plurality of first AI tools in the AI model that are available to the first autonomous AI agent, by analyzing a plurality of embeddings that represent the corpus of data using the clustering tool as a result of the subsets corresponding to respective attributes; and   selecting, by the first autonomous AI agent, the relevant data from the respective clusters using the first selected AI tool.   
     
     
         16 . The method of  claim 12 , wherein the method further comprises:
 training the second selected AI tool using the validity determination.   
     
     
         17 . The method of  claim 12 , further comprising at least one of the following:
 triggering the first autonomous AI agent to select the relevant data from the corpus of data by providing a first AI prompt, which identifies the corpus of data, as an input to the first autonomous AI agent, the first AI prompt specifying that a purpose of the first autonomous AI agent is to select the relevant data from the corpus of data;   triggering the second autonomous AI agent to generate the maliciousness determination by providing a second AI prompt together with designated contextual information as inputs to the second autonomous AI agent, wherein the second AI prompt specifies that a purpose of the second autonomous AI agent is to determine whether the entity exhibits the malicious behavior, wherein the designated contextual information comprises the relevant data, and wherein the designated contextual information comprises context regarding the second AI prompt; or   triggering the third autonomous AI agent to generate the validity determination by providing a third AI prompt together with specified contextual information as inputs to the third autonomous AI agent, wherein the third AI prompt specifies that a purpose of the third autonomous AI agent is to determine whether the maliciousness determination is valid, wherein the specified contextual information comprises the relevant data and the maliciousness determination, and wherein the specified contextual information comprises context regarding the third AI prompt.   
     
     
         18 . The method of  claim 12 , further comprising:
 generating, by the first autonomous AI agent, a data report that indicates the relevant data;   as a result of the first autonomous AI agent generating the data report, receiving an assessment of the data report from a user, the assessment indicating a change to be made to the relevant data; and   training the first autonomous AI agent using the assessment.   
     
     
         19 . The method of  claim 12 , further comprising:
 generating, by the second autonomous AI agent, a maliciousness report that indicates the maliciousness determination;   as a result of the second autonomous AI agent generating the maliciousness report, receiving an assessment of the maliciousness report from a user, the assessment indicating a revised maliciousness determination, which differs from the maliciousness determination indicated by the maliciousness report, the revised maliciousness determination indicating whether the entity exhibits the malicious behavior; and   training the second autonomous AI agent using the assessment.   
     
     
         20 . The method of  claim 12 , further comprising:
 generating, by the third autonomous AI agent, a validity report that indicates the validity determination;   as a result of the third autonomous AI agent generating the validity report, receiving an assessment of the validity report from a user, the assessment indicating a revised validity determination, which differs from the validity determination indicated by the validity report, the revised validity determination indicating whether the maliciousness determination is valid; and   training the third autonomous AI agent using the assessment.   
     
     
         21 . A computer program product comprising a computer-readable storage medium having instructions recorded thereon for enabling a processor-based system to perform operations, the operations comprising:
 executing a first autonomous artificial intelligence (AI) agent that, in response to receiving an inquiry that asks whether an entity exhibits malicious behavior, selects relevant logs from a plurality of logs using a first selected AI tool as a result of the relevant logs being associated with the entity, wherein the first selected AI tool is selected by the first autonomous AI agent from a plurality of first AI tools in an AI model that are available to the first autonomous AI agent;   executing a second autonomous AI agent that, in response to receiving the relevant logs from the first autonomous AI agent, generates a maliciousness determination by analyzing the relevant logs using a second selected AI tool, wherein the maliciousness determination indicates whether the entity exhibits the malicious behavior, and wherein the second selected AI tool is selected by the second autonomous AI agent from a plurality of second AI tools in the AI model that are available to the second autonomous AI agent;   executing a third autonomous AI agent that generates a validity determination by analyzing the maliciousness determination using a third selected AI tool, wherein the validity determination indicates whether the maliciousness determination is valid, and wherein the third selected AI tool is selected by the third autonomous AI agent from a plurality of third AI tools in the AI model that are available to the third autonomous AI agent; and   as a result of an analysis that takes into consideration the validity determination, triggering execution of an instruction that causes a statement to be provided via a user interface, the statement indicating whether the entity exhibits malicious behavior.

Join the waitlist — get patent alerts

Track US12609960B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.